PT-2024-27774 · Itsourcecode · Itsourcecode Payroll Management System

Chenshan

+9

·

Published

2024-06-14

·

Updated

2024-08-01

·

CVE-2024-37831

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Itsourcecode Payroll Management System version 1.0
Description The issue is related to SQL Injection in the payroll items.php file via the ID parameter. This allows for potential exploitation.
Recommendations For Itsourcecode Payroll Management System version 1.0, consider restricting access to the payroll items.php file or the ID parameter to minimize the risk of exploitation until a fix is available.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-37831

Affected Products

Itsourcecode Payroll Management System